@finance-ui/finance-view@99.9.1
Malicious code in @finance-ui/finance-view (npm)
Analysis
@finance-ui/finance-view@99.9.1 is a dependency-confusion stub with no functional code. Its package.json declares a dependency on a tarball hosted at ltidi[.]storage[.]googleapis[.]com/depenconf/ltidisafe-3.3.6.tgz — a non-registry URL that delivers the actual payload on install. The package uses version 99.9.1 to out-rank any legitimate internal package with a similar name. The sole file (index.js) is empty (module.exports = {}); the package has no repository, no description, and no README. Installing this package causes npm to fetch and execute the remote tarball from Google Storage CDN.
- analyzed by
- Leitwacht
- first seen
- Jul 14, 2026, 03:17 AM
- analyzed
- Jul 14, 2026, 03:20 AM
Related advisories
- @finance-ui/snackbar-ifpe@99.9.1
- elsisi-cli@9.9.9
- chai-as-auth@2.3.5
- polymarket-bot-logger@1.0.1
- @sqlite-panel/createsql@1.0.0
- type-swap@3.1.3
- test_adminet@99.9.9
- monitoring-service-util@1.0.0
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.